Техническая информация
- '%TEMP%\pukka.exe'
- '<SYSTEM32>\ntvdm.exe' -i1
- %TEMP%\scs9118.tmp
- %TEMP%\scs9241.tmp
- %TEMP%\manfa.exe
- %TEMP%\pukka.exe
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\6P5SDOMI\2904UKwm[1].zip
- %TEMP%\scs9241.tmp
- %TEMP%\scs9118.tmp
- 'ma####erfumes.com':80
- ma####erfumes.com/images/stories/fruit/2904UKwm.zip
- DNS ASK ma####erfumes.com
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b0c.b18.b34'